WHMCS 9.0.8 Security Update
Unauthenticated Remote Code Execution (CVE-2026-67399)
Default Update CMD
Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).
9.0.8 (Maintenance Release) Security Fixes
WHMCS 9.0.8 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.
Unauthenticated Remote Code Execution (CVE-2026-67399)
This is the most serious issue in the release. CVE-2026-67399 is an unauthenticated remote code execution flaw. An attacker with no account can submit a forged payload that WHMCS processes without adequate restrictions, and under specific conditions this leads to arbitrary code execution on the server. The vulnerability has been present since WHMCS 8.0 and affects every build before 8.13.7 (8.x) or 9.0.8 (9.x).
The likely mechanism is insecure deserialization / PHP object injection: attacker-controlled data is turned back into live objects that WHMCS then trusts. Because it is reachable with no login and there is no customer-side workaround, the update is the only fix. An attacker who succeeds gains full control of the WHMCS host, including the billing database, client records, and payment details.
Customer Data Disclosure via 2Checkout Gateway (CVE-2026-67398)
CVE-2026-67398 is a missing authorization flaw in the 2Checkout payment gateway module. An unauthenticated user can hit the gateway endpoint and, under specific conditions, retrieve a customer’s personally identifiable information: name, mailing address, city, state, postal code, country, email, and phone number.
It only affects installations that run the 2Checkout module, and the affected range reaches back to WHMCS 4.5.0. The CVSS 4.0 score is 8.2 (High). Unlike the RCE, this one has an interim mitigation: deactivate the 2Checkout payment gateway module until you can update, then switch payments to an alternative gateway.
Affected Versions and Remediation
Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.
How to Apply the Fix
Update WHMCS to the latest patch release of your branch, then confirm the version in Help > About WHMCS.
Utilities → Update WHMCS (in the Admin Area)
References
Check your system for vulnerabilities
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Check Your System